Skip to main content Scroll Top
Privacy Notice

Book Your Own Adventures

Privacy Notice

Last updated: 03/10/2026

This notice explains how personal data are processed when you visit acla.fondazionecomel.org (the “Website”) or contact ACLA through it. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”) and the Italian Personal Data Protection Code (Legislative Decree 196/2003, as amended). It applies only to this Website, not to other websites you may reach through links.

1. Data controller

The Website is owned and operated by Institutio Santoriana – Fondazione Comel (the “Foundation”), registered office Via F.lli Maggiolini 1, 20122 Milan, Italy, tax code 97117040150, which is the data controller.
Contact for any privacy matter: segreteria@fondazionecomel.org.

2. Data we process, purposes and legal bases

2.1 Browsing data

The servers and software that run the Website automatically collect certain data whose transmission is implicit in the use of internet protocols. These include the IP address of your device, the date and time of the request, the address of the page requested, the method and result of the request, the size of the response and information about your browser and operating system.

These data are used only to operate the Website, to keep it secure (for example, to detect and block attacks) and to produce aggregated statistics. The legal basis is the Foundation’s legitimate interest in providing a working and secure website (Article 6(1)(f) GDPR). They may be made available to the competent authorities if needed to investigate offences against the Website.

2.2 Data you send us

The Website has no forms that collect personal data. If you write to us at the e-mail addresses shown on the Website, for example info@acla.fondazionecomel.org, we receive your e-mail address and any other personal data you include in your message.

We use these data only to reply to you and to deal with your request, such as information about our activities, attendance at an event or membership. The legal basis is the performance of steps you request (Article 6(1)(b) GDPR) and our legitimate interest in answering correspondence (Article 6(1)(f) GDPR).

2.3 Cookies

The Website does not set cookies on its public pages and does not use cookies for analytics, advertising or profiling. Technical cookies may be set only for users who log in to the Website’s administration area.

2.4 Content from third parties

To display the Website, your browser downloads some content directly from third-party servers. When this happens, those providers receive your IP address and the technical data your browser normally sends:

  • Google Fonts (Google Ireland Limited / Google LLC), used for the Website’s typefaces, on all pages; see Google’s privacy policy.

Event pages show the venue address with a link to Google Maps; no map is loaded unless you follow that link.

3. How data are processed and who receives them

Data are processed electronically by staff and collaborators authorised by the Foundation, with security measures designed to prevent loss, misuse and unauthorised access.

They may also be processed by the Foundation’s technical service providers, acting as data processors under Article 28 GDPR: the hosting provider of the Website (Register S.p.A., Italy), the e-mail provider (Microsoft), and the IT consultants who maintain the Website.

Data are not sold and are not disclosed to other third parties, except where required by law.

4. Transfers outside the European Economic Area

Our e-mail provider, Microsoft, stores and processes the data of its European business customers within the European Union under its EU Data Boundary, with limited exceptions. Google, which provides the typefaces described in section 2.4, may process data in the United States. Any transfer outside the European Economic Area relies on the European Commission’s adequacy decision for the EU–US Data Privacy Framework or, where applicable, on standard contractual clauses (Article 46 GDPR).

5. Retention

Browsing data in server logs are deleted automatically on a rolling basis, unless needed for longer to investigate a security incident.

6. Your rights

You have the right to access your personal data and to obtain their rectification, erasure or restriction of processing. You also have the right to data portability where applicable, and the right to object to processing based on legitimate interest (Articles 15–22 GDPR). Where processing is based on consent, you may withdraw it at any time without affecting earlier processing.

To exercise your rights, write to segreteria@fondazionecomel.org.

You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or with the authority of the EU country where you live or work.

7. Whether you must provide data

Apart from browsing data, providing personal data is voluntary. If you do not provide the data needed to answer your request, we may not be able to reply.

8. Automated decisions

No decisions based solely on automated processing, including profiling, are taken.

9. Changes

This notice may be updated. The date of the latest version is shown at the top.